← Back to Skin Overdraft

Privacy Policy

Last updated: March 2026

Who We Are

Skin Overdraft is a book by Rolf. This website (skin-insights.co) is operated by Cultur3 Numomo AG (CHE-400.275.415), Talbachstrasse 2, 8418 Schlatt ZH, Switzerland. Contact: legal@rolfskincare.com.

What We Collect

When you sign up for email updates, we collect:

We do not collect names, payment information, or browsing behavior beyond what is described below.

How We Use Your Data

We will never sell, rent, or share your email address with third parties for their own marketing purposes.

Lawful Basis

We process your personal data based on your consent, given when you voluntarily submit the email signup form. You may withdraw consent at any time by unsubscribing or contacting us. Applicable data protection law: Swiss Federal Act on Data Protection (FADP/nDSG). If you are in the EU, GDPR also applies.

Data Processors

We use the following third-party services to operate this website. Each processes your data solely on our behalf:

International Data Transfers

Our data processors (Brevo, Turso, Vercel) may process data outside Switzerland. These transfers are covered by the processors' standard contractual clauses and data processing agreements. Switzerland has been recognized by the EU as providing adequate data protection.

Cookies & Tracking

This site uses only essential storage:

We do not use any analytics cookies or third-party tracking pixels.

Data Retention

We retain your email address and signup data for 24 months after your last interaction (email open, click, or signup). After that period, your data is deleted. ARC (advance reader) data is deleted 6 months after the book launch unless you separately opt into the general mailing list.

Your Rights

Under the Swiss Federal Act on Data Protection (FADP), you have the right to:

To exercise any of these rights, email legal@rolfskincare.com. We will respond within 30 days.

Data Storage & Security

Your data is stored in a database hosted on Turso (edge-distributed SQLite). Data is encrypted in transit (TLS) and at rest. Access is restricted to authenticated API endpoints only.

Changes

If we update this policy, we'll note the date above. Material changes will be communicated via email to active subscribers.